Risk Consulting - Risk Technology - SAP GRC & Security - Senior Consultant
Listed on 2026-06-13
-
IT/Tech
SAP Consultant, Cybersecurity, IT Consultant, Systems Analyst
Location
Atlanta, Chicago, New York, Hoboken, Pittsburgh, Philadelphia, Cleveland, Akron, Dallas, Los Angeles
Role OverviewWith rapid growth across SAP and Governance, Risk, and Compliance (GRC), EY seeks SAP Security and GRC professionals to support improved business performance through SAP Application Security and GRC solutions as a Senior Consultant in Risk Technology. The role involves design, configuration, and implementation of SAP Security and GRC capabilities across transformation initiatives, working with experienced managers, partners, and clients in complex SAP environments.
WhatWe Look For
Candidates with a strong technical foundation and hands‑on implementation experience in SAP Application Security and GRC, who are eager to deepen their skills within EY’s standard tools, methodologies, and delivery approaches. The role is suited for individuals who enjoy solving complex problems, collaborating within project teams, and strengthening clients’ SAP security and compliance environments.
Key Responsibilities- Design, configure, and implement SAP Application Security and SAP GRC Access Control solutions across SAP environments.
- Assist with SAP transformation initiatives, including S/4
HANA and cloud‑based SAP solutions. - Perform security role design, user provisioning, access reviews, and Segregation of Duties (SoD) analysis in alignment with defined risk frameworks.
- Support SAP audit activities (internal and external), including evidence collection, issue remediation, and control documentation.
- Collaborate with functional and technical stakeholders to gather requirements and document security‑related processes.
- Contribute to the development of deliverables, work papers, and client‑facing documentation.
- Work effectively within onshore and offshore delivery models as part of a broader project team.
- Stay current on SAP Security, GRC tools, and industry developments through training and on‑the‑job learning.
- Hands‑on experience supporting SAP Security and SAP GRC Access Control implementations.
- Understanding of SAP Application Security concepts across on‑premise, cloud, and SaaS SAP applications.
- Ability to execute defined tasks independently while escalating risks and issues appropriately.
- Strong analytical, problem‑solving, and documentation skills.
- Effective written and verbal communication skills, with the ability to work collaboratively across teams.
- Comfort working in fast‑paced environments with shifting priorities.
- 3–5+ years of experience supporting SAP Security and/or SAP GRC engagements.
- Required bachelor’s degree in computer science, information systems, information security, or a related field (preferred).
- Hands‑on experience with Design, Build, Test, and Deploy activities for SAP Application Security across systems such as SAP ECC, S/4
HANA, FIORI, ARIBA, HCM, or Success Factors. - Experience supporting SAP GRC Access Control (e.g., version 12.0 or similar technologies), including exposure to IAM integrations (e.g., Saviynt, SailPoint, SAP IAG).
- Experience supporting SoD and Critical Action rule sets, access provisioning, and emergency access processes.
- Ability to manage multiple work streams with guidance and supervision.
- Willingness to travel based on client needs (estimated up to 80%); valid U.S. driver’s license and passport required.
- Progress toward or interest in obtaining relevant certifications (e.g., CISA, SAP Security, SAP GRC).
- Exposure to SAP audit processes and regulatory or compliance frameworks (e.g., SOX, GDPR).
- Familiarity with tools such as Service Now or HP ALM.
- Awareness of emerging SAP technologies such as BTP, SAC, AI, or RPA.
- Comprehensive compensation and benefits package with performance‑based rewards and recognition.
- Base salary ranges: $102,500 to $187,900 for U.S. locations; $122,900 to $213,400 for New York City Metro Area, Washington State, and California (excluding Sacramento).
- Medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
- Hybrid work model: most external, client‑serving roles work together in person 40–60% of the time.
- Flexible vacation policy with ability to…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).